GDID is the persistent Windows ID that helped FBI trace a Scattered Spider hacker despite VPNs. Here's how it works and how to limit it.

you are viewing a single comment's thread
view the rest of the comments
[–] 19 points 1 week ago (2 children)

Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID

To me the problem is not some uuid in some file/registry entry. The issue is, that somehow MS knows what webpages you visit??? why is this transferred? full log of what you do? edge? firefox? system service reporting outgoing IP connections? WTF.

  • source
  • hideshow 4 child comments
  • [–] 4 points 1 week ago* (1 child)

    I was asking the same question, quoting that exact excerpt in a different thread... and getting pretty hairbrained responses.

    After a little bit of digging, I can see ngrok has a sign in option where you can sign in with a GITHUB account.

    I suspect that's how Microsoft has a record of someone interacting with that specific website.

    Still am unclear how the browser has access to this id, which sounds like it's a registry setting. If browsers are able and willing to just fork over arbitrary registry values when asked, that's a major issue.

    And if it's not arbitrary... just THAT value, it seems to suggest complicity on the browsers themselves.

    Can I see this id egressing my system if I'm snooping with wireshark? I really really want to understand how and when this value is going over the wire.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 1 week ago

    if the hacker signed in with his github.... I would assume it's something hidden behind "telemetry" or such - but either way it's horrible. And the article is bad for just mentioning this without going into detail.

  • source
  • parent